Browser AgentBLOCK
A Model Context Protocol (MCP) integration that provides Claude Desktop with autonomous browser automation capabilities. This agent enables Claude to interact with web content, manipulate DOM elements, execute JavaScript, and perform API requests.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://archestra.ai/mcp-catalog/imprvhub__mcp-browser-agent) [](https://smithery.ai/server/imprvhub/mcp-browser-agent)
A powerful Model Context Protocol (MCP) integration that provides Claude Desktop with autonomous browser automation capabilities.
Features
- Advanced Browser Automation
- Navigate to any URL with customizable load strategies
- Capture full-page or element-specific screenshots
- Perform precise DOM interactions (click, fill, select, hover)
- Execute arbitrary JavaScript in browser context with console logs capture
- Powerful API Client
- Execute HTTP requests (GET, POST, PUT, PATCH, DELETE)
- Configure request headers and body content
- Process response data with JSON formatting
- Error handling with detailed feedback
- MCP Resource Management
- Access browser console logs as resources
- Retrieve screenshots through MCP resource interface
- Persistent session with headful browser instance
- AI Agent Capabilities
- Chain multiple browser operations for complex tasks
- Follow multi-step instructions with intelligent error recovery
- Technical task automation through natural language instructions
Demo
eae391244e85OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-browser-agent -- npx -y [email protected]
{
"mcpServers": {
"mcp-browser-agent": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (13)
7 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
api_delete | destructive | Perform a DELETE request to an API endpoint |
api_get | read | Perform a GET request to an API endpoint |
api_patch | write | Perform a PATCH request to an API endpoint |
api_post | write | Perform a POST request to an API endpoint |
api_put | write | Perform a PUT request to an API endpoint |
browser_click | read | Click an element on the page |
browser_evaluate | write | Execute JavaScript in the browser context |
browser_fill | read | Fill a form input with text |
browser_hover | read | Hover over an element on the page |
browser_navigate | read | Navigate to a specific URL |
browser_screenshot | read | Capture a screenshot of the current page or a specific element |
browser_select | read | Select an option from a dropdown menu |
browser_set_viewport | write | Change the browser |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
const result = eval(script);
api_delete
assert.equal(safeScreenshotName('../../.ssh/authorized_keys'), 'authorized_keys');const result = await server.call('browser_navigate', { url: `file://${os.homedir()}/.ssh/id_rsa` });assert.equal(safeScreenshotName('../../.ssh/authorized_keys'), 'authorized_keys');const shot = await server.call('browser_screenshot', { name: '../../escape', savePath: outDir });siteUrl = `http://127.0.0.1:${site.address().port}`;@modelcontextprotocol/sdk, @types/node, shx, typescript
have the model open a local file (an SSH key, a credentials file) and pass it to an
Gates applied: no_behavioural_pass.
eae391244e85full audit observations/trust-audit/mcp-server/imprvhub__browser-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | eae391244e85 | BLOCK | D | 69 | first audit |
Questions
What is the Browser Agent MCP server?
A Model Context Protocol (MCP) integration that provides Claude Desktop with autonomous browser automation capabilities. This agent enables Claude to interact with web content, manipulate DOM elements, execute JavaScript, and perform API requests.
What tools does Browser Agent expose?
13 in total: 7 read-only, 5 that write, and 1 that can delete or overwrite (api_delete). Every one is listed on this page with its risk.
Is Browser Agent safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Browser Agent need?
No credential environment variables were found in its source, so it appears to need none.
How does Browser Agent run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-browser-agent at 0.10.0.
How current is this page?
The grade is for one exact copy of the source (eae391244e85), read on 2026-10-08. The repository is watched and re-audited when it changes.